Posts
3370
Following
712
Followers
1579
"I'm interested in all kinds of astronomy."
repeated

CVE-2024-26926 Binder n-day analysis.
It is labeled EoP in Android Security Bulletin (Is it really exploitable?)

https://github.com/MaherAzzouzi/LinuxKernel-nday/blob/main/CVE-2024-26926/CVE_2024_26926_Analysis.pdf

0
2
0
repeated

A quick newsletter post on the dehumanization behind Satya Nadella's remarks about copyright law

https://buttondown.com/maiht3k/archive/virtual-employees-and-remixing-machines-devalue/

1
6
0
repeated

TrendAI Zero Day Initiative

That's a wrap for Ireland 2024! Over last 4 days, we awarded $1,066,625 for over 70 0-day bugs. That makes 4 contests in a row that exceeded the million-dollar mark. Congratulations to the Viettel Cyber Security team for winning Master of Pwn with 33 points and $205,000.

0
2
0
Oracle VM VirtualBox 7.0.10 r158379 Escape

https://zeroclick.sh/blog/cve-2023-22098/
0
0
2
Memory Management - Part 1: Virtual memory and Paging concepts

https://blog.reodus.com/posts/memory-management-part1/
0
0
2
repeated

Seasonal Spells for

Toddler's Vicious Snot: This spell initially impacts the member of the party with the lowest HP. It lasts for 2 days. After that it affects all other members of the party, is immune to Healing, and you need a 20+ Con saving throw to recover from it.

Fall Back: This spell interrupts the target's Long Rest one hour too soon. Every time. For about two weeks.

Toddler's Disappearing Accessories: This spell affects hats, gloves, scarves, and boots.

0
1
1
CVE-2024-9050: NetworkManager-libreswan IPSec VPN plugin local code execution

https://www.openwall.com/lists/oss-security/2024/10/25/1
0
0
0
repeated

The thing where companies make websites for their own executives, who never visit them, instead of their customers, who are forced to.

0
3
0
SEC Consult SA-20241024-0 :: Unauthenticated Path Traversal Vulnerability in Lawo AG - vsm LTC Time Sync (vTimeSync) (CVE-2024-6049)

https://seclists.org/fulldisclosure/2024/Oct/7
0
0
0
repeated

This makes me want to scream and pull out my hair.

"Reduce your vocabulary by 10-20% to prove you're a human."

5
17
2
repeated

The Apple Security Research blog now has an RSS feed, though it’s not properly advertised.

https://security.apple.com/blog/feed.rss

0
2
0
repeated

A vulnerability in the Common Log File System (CLFS) driver allows a local user to gain elevated privileges on Windows 11 https://ssd-disclosure.com/ssd-advisory-common-log-file-system-clfs-driver-pe/

0
1
0
repeated

Has anyone attempted to calculate the overall environmental / energy consumption of Electron, vs if the most popular applications using it were rewritten in a more efficient native framework?

1
1
0
repeated

It has now been twelve years since the paper "The most dangerous code in the world: validating SSL certificates in non-browser software" was published.

My blog post about it from back then: https://daniel.haxx.se/blog/2012/10/25/libcurl-claimed-to-be-dangerous/

It'd be interesting to know how much HTTPS clients are still skipping cert verification in the wild. I bet it is still widespread.

1
1
0
[RSS] It rather involved being on the other side of the airtight hatchway: Defeating ASLR after you've gained RCE via ROP

https://devblogs.microsoft.com/oldnewthing/20241024-00/?p=110417
0
0
0
[RSS] Tales from the Call-Gate: An SMM Supervisor Vulnerability

https://labs.ioactive.com/2024/10/tales-from-call-gate-smm-supervisor.html
0
1
3
repeated

"Inside the U.S. Government-Bought Tool That Can Track Phones at Abortion Clinics"

An excellent @404mediaco investigation into "Locate X", a tracking tool that uses ad-tracking tech -- specifically, "mobile advertising identifiers" -- to follow people around

https://www.404media.co/email/f4992514-a605-4579-9a75-3d0707758e03/

3
4
0
Show older